CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
5488 | CVE-2002-1101 | Candidate | Cisco VPN 3000 Concentrator 2.2.x, 3.6(Rel), and 3.x before 3.5.5, allows remote attackers to cause a denial of service via a long user name. | Proposed (20030317) | ACCEPT(4) Baker, Cole, Green, Jones | NOOP(1) Cox | REVIEWING(1) Christey | Christey> Possible dupe of CVE-2002-1100 ?? Need to review the bug log | in the Cisco advisory. | View |
2644 | CVE-2000-1076 | Candidate | Netscape (iPlanet) Certificate Management System 4.2 and Directory Server 4.12 stores the administrative password in plaintext, which could allow local and possibly remote attackers to gain administrative privileges on the server. | Proposed (20001129) | ACCEPT(3) Baker, Frech, Mell | NOOP(2) Christey, Cole | Christey> Partial vendor acknowledgement at: | http://docs.iplanet.com/docs/manuals/cms/42/relnotes/release_notes.html | "By default, Administration Server administrator"s password | (also known as the SIE password) is stored in clear text in the | adm.conf file. | This does not usually pose a security threat because most | administrators use their Operating System"s security features to | ensure that the file is protected from other users." | View |
5332 | CVE-2002-0944 | Candidate | Cross-site scripting vulnerability in DeepMetrix LiveStats 5.03 through 6.2.1 allows remote attackers to execute arbitrary script as the LiveStats user via the (1) user-agent or (2) referrer, which are not filtered by the stats program. | Modified (20030325-01) | ACCEPT(4) Baker, Cole, Frech, Green | NOOP(4) Christey, Cox, Foat, Wall | Christey> On February 19, 2003, DeepMetrix confirmed via email that this | bug has been corrected in LiveStats 6.2.2. | | CONFIRM:http://www.deepmetrix.com/log_analyzer/xsp/service/release_notes/index.asp | | As of February 19, this URL only mentions the User-Agent bug, | but the vendor again confirmed via email that the referrer is | also addressed. | View |
7637 | CVE-2003-0813 | Candidate | A multi-threaded race condition in the Windows RPC DCOM functionality with the MS03-039 patch installed allows remote attackers to cause a denial of service (crash or reboot) by causing two threads to process the same RPC request, which causes one thread to use memory after it has been freed, a different vulnerability than CVE-2003-0352 (Blaster/Nachi), CVE-2003-0715, and CVE-2003-0528, and as demonstrated by certain exploits against those vulnerabilities. | Assigned (20030918) | NOOP(1) Christey | Christey> Note: MS04-012 references this CAN and credits eEye, who | describes a similar-looking issue in their advisory COMMENT | "AD20040413A." However, this particular candidate was published by | ISS in 2003. MITRE is investigating this discrepancy and will update | this candidate if necessary. | View |
5646 | CVE-2002-1262 | Candidate | Internet Explorer 5.5 and 6.0 does not perform complete security checks on external caching, which allows remote attackers to read arbitrary files. | Proposed (20030317) | ACCEPT(3) Cole, Green, Wall | NOOP(2) Christey, Cox | Christey> NOTE: Early versions of Microsoft bulletin MS02-069 | also assigned for a "user.dir exposure" issue. This | candidate should *ONLY* be used for the external caching issue | as covered in MS:MS02-068; the "user.dir" issue is identified | by CVE-2002-1365. | View |
Page 294 of 20943, showing 5 records out of 104715 total, starting on record 1466, ending on 1470